An assignment places a module's directories and its accesses (hq 153)
A definition names no host path (ADR 0112); an adopted machine keeps its
data where the predecessor put it. Two settings, validated like endpoints:
places: {<directory id>: <path> | {path, owner}}
accesses: {<access id>: <path>}
An access may now be declared by id (`{"id": "series", "mode": "read-write"}`)
and named in mounts, env and content as ${access:<id>}; the assignment
says where it is on this node, and an access nobody placed is refused by
name. A definition still carrying a path keeps it as the default the
assignment replaces. A placed directory takes the assignment's owner
where it says one. Resolved in composition, so the host receives paths
and owners exactly as before.
This commit is contained in:
@@ -473,9 +473,15 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
||||
// find each present — refusing clearly if the operator has not provided it — before it
|
||||
// starts anything that depends on it. The mesh creates, chowns and reconciles none of it;
|
||||
// an `access` resource says only *this path must exist, and this module reaches it*.
|
||||
for _, a := range m.Accesses {
|
||||
// Where each is on THIS machine is the assignment's (novox/hq issue 153): placed by id
|
||||
// where the operator said, the definition's default otherwise, refused where neither.
|
||||
accesses, accessPaths, err := accessesFor(m, with.Settings[m.Module])
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
for _, a := range accesses {
|
||||
first = append(first, map[string]any{
|
||||
"id": AccessID(a.Path), "type": "access", "path": a.Path, "mode": a.At(),
|
||||
"id": AccessID(a.Path), "type": "access", "path": a.Path, "mode": a.Mode,
|
||||
})
|
||||
}
|
||||
for _, to := range m.SecretRequirements() {
|
||||
@@ -670,6 +676,12 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
||||
}
|
||||
// And where this node places the directories the module declared without a path
|
||||
// (novox/hq ADR 0112) — resolved once per module, named by ${dir:…} from any resource.
|
||||
// — and, on an adopted machine, where the assignment says they already are, with the
|
||||
// owner the data already has (novox/hq issue 153). Malformed placements are refused here.
|
||||
placed, err := Places(m, with.Settings[m.Module])
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
dirs := dirsFor(m, with)
|
||||
// And the machine underneath, which no binding of its own can tell it.
|
||||
thisMachine := machineFacts(r, with.Names, with.MeshRange)
|
||||
@@ -710,6 +722,12 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
||||
if err := dirInto(copied, dirs, m.Module); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
// The operator's data the same way: ${access:…} becomes where this node keeps it,
|
||||
// and a placed directory takes the owner the assignment said (issue 153).
|
||||
if err := accessInto(copied, accessPaths, m.Module); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
ownerInto(copied, placed)
|
||||
// **After settings, and that is the whole reason it is here.** A module's file
|
||||
// content is where a setting lands, so a placeholder may only exist once the setting
|
||||
// has been put in — filling secrets first would look at content that is not yet what
|
||||
|
||||
Reference in New Issue
Block a user